NewsCryptoWhite Hats Rescue $4.5 Million in Bitcoin From Coldcard Exploit

White Hats Rescue $4.5 Million in Bitcoin From Coldcard Exploit

Author: Blockonomi·

Key Takeaways

  • •White-hat researchers secured 52.37 BTC worth over $4.5 million from the Coldcard exploit and moved the funds into Crypto Recovery Trust, which plans to process claims from verified victims.
  • •The rescued coins account for only about 2.8% of the Bitcoin tied to the exploit, as Galaxy Digital tracked total losses of 1,789.28 BTC valued at roughly $154.1 million.
  • •Coinkite traced the attacks, which began on July 31, to a firmware bug that forced some devices to rely on a software random generator, allowing attackers to derive predictable wallet seeds and access funds.
  • •The rescue consolidated coins from Wave 2 and Footprints AA, AU, and AX into a fresh address in block 967,948, marked with an OP_RETURN message pointing potential claimants to the trust's claims process.
  • •Nick Bax of Ump Labs confirmed he helped protect roughly 50 BTC, stating that thieves were close to taking the funds before the intervention.
White Hats Rescue $4.5 Million in Bitcoin From Coldcard Exploit

White-hat researchers have secured 52.37 BTC, worth more than $4.5 million, from the exploit targeting Coinkite's Coldcard hardware wallets, moving the funds into a Wyoming trust and opening a recovery path for affected users. Galaxy Digital researcher Alex Thorn said Crypto Recovery Trust now controls the address holding the rescued Bitcoin and plans to process claims from verified victims.

Thorn said the rescued funds represent about 2.8% of the Bitcoin connected to the exploit. According to his post, the transfer consolidated coins from Wave 2 and Footprints AA, AU, and AX into a fresh address in block 967,948, marked with an OP_RETURN message reading "claim:cryptorecoverytrust dot com." OP_RETURN is a Bitcoin feature that lets users embed short pieces of data in a transaction, leaving a permanent, publicly visible record on the blockchain; in this case, the note points potential claimants to the trust's claims process.

COLDCARD WHITE HAT MOVES FUNDS TO TRUST

52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948

these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ

— Alex Thorn (@intangiblecoins) September 21, 2026

Nick Bax of Ump Labs confirmed in a post on X (@bax1337) that he helped protect roughly 50 BTC, saying thieves were close to taking the funds before the rescue. The move gives affected Coldcard users a route to recover their losses. White-hat interventions of this kind, in which security researchers secure vulnerable funds before thieves can reach them, have become a recognized pattern in crypto incident response.

Firmware Bug Exposed Wallet Seeds

The attacks began on July 31 and targeted Bitcoin held through Coldcard hardware wallets produced by Coinkite. Hardware wallets are built to keep the private keys that control coins offline, and their security rests on the seed generated when a device is set up, the data from which all wallet credentials are derived. Coinkite traced the weakness to a firmware bug affecting seed generation. The flaw forced some devices to rely on a software random generator, allowing attackers to use predictable seed data to identify wallet credentials and access funds.

Galaxy Digital tracked 1,789.28 BTC lost during the attacks, an amount worth about $154.1 million at prevailing Bitcoin prices.

Users Shift Bitcoin After Attacks

Coinkite urged users to update the affected software or transfer their holdings away from vulnerable devices. In response, some users moved their Bitcoin to other storage services, including exchanges. According to the company, the flaw went undetected through successive product releases, each of which continued to carry the faulty code, extending the window in which devices running the affected software could generate predictable seeds.

Other Security Incidents

The Coldcard case is among several security events to affect crypto firms in recent weeks. In a separate case, an MEV bot intervened to stop an Ethereum wallet exploit before an attacker could drain $7.8 million, and KelpDAO froze the destination address for 24 hours.

A customer data breach at Revolut exposed information belonging to 680 customers after fraudulent requests bypassed the company's verification checks. Revolut reported the incident to regulators during a security review.

Security threats also continue across the wider crypto market. In one recent campaign, North Korean actors used fake job offers to compromise more than 30,000 devices, and researchers linked the operation to thefts from over 7,000 cryptocurrency wallets.

Trust Begins Victim Recovery Process

Crypto Recovery Trust is holding the rescued assets while it verifies ownership claims from affected users. The Wyoming structure gives the trust a legal mechanism for safeguarding funds during the recovery period, one that white hats can rely on while investigators continue tracing stolen Bitcoin.

Investigators are reviewing the Coldcard hack and tracing addresses tied to stolen funds. Coinkite has urged affected users to follow its security guidance, and the recovery trust may release the rescued Bitcoin to claimants once it confirms rightful ownership. With the rescued coins covering only a small share of the 1,789.28 BTC Galaxy Digital tracked as lost, further recoveries depend on that tracing work and on the trust's verification of each claim.

Source: Blockonomi